Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers
Revolut disclosed customers’ passports, verification selfies and Bitcoin transaction histories after treating a fraudulent authorities request as reputable.
Affected customers had been instructed Friday that the disclosed data may embrace passport or driver’s license copies, verification selfies, names, dates of beginning, occupations, house addresses, cellphone numbers, IBANs, and account statements. Withdrawal information and full transaction histories, together with Bitcoin exercise, may have been launched.
The request got here from an unauthorized mailbox working inside the area infrastructure of a real authorities company and carried legitimate authentication credentials.
Revolut subsequently contacted the company, concluded the request was fraudulent, blocked the tackle and started notifying customers and regulators. The firm has not recognized the company or disclosed what number of customers had been affected.
Compliance calls for sharpen buyer backlash
The incident has drawn scrutiny over how a lot data monetary establishments gather from customers and the controls used when governments later search entry to these information.
Marc Zeller, founder of the Aave Chan Initiative, mentioned the disclosure got here shortly after Revolut demanded further data from him, threatening to shut his account.
“The infuriating half is that it occurs proper after Revolut despatched me a notification to supply a LOT of information or ‘we’ll shut your account in 20 days,’” Zeller said. He accused the firm of doing the attackers’ work for them after the request fooled him.
The criticism cuts into a rigidity created by trendy monetary compliance. Banks and fintech companies gather intensive id and transaction information to fulfill know-your-customer and anti-money laundering necessities. Those databases change into particularly delicate once they hyperlink verified identities and residential data to cryptocurrency exercise.
For Bitcoin holders, the uncovered information may give an attacker excess of a monetary assertion. Bitcoin transactions are recorded on a public blockchain, which means data tying a identified individual to particular exercise can probably assist map that particular person’s wider onchain footprint.
Onchain investigator ZachXBT, who publicized the incident, said the disclosure appeared restricted in scale and could have focused high-net-worth customers. Revolut has not supplied a determine that might set up the scope of the incident.
No buyer funds have been reported stolen, and the data described in Revolut’s notices didn’t embrace passwords, card PINs or cryptocurrency non-public keys.
The quick danger as an alternative stems from the mixture of id paperwork, contact data, residential addresses and monetary histories now probably out there to the attacker.
A real authorities area defeated Revolut’s checks
The technique used to acquire the data leaves a separate downside for Revolut and probably different monetary establishments that obtained requests from the similar supply.
The fraudulent e mail handed SPF, DKIM and DMARC authentication, mechanisms designed to assist confirm that messages are licensed by the area they declare to signify.
That suggests the attacker had entry to an unauthorized mailbox inside the authorities company’s precise e mail infrastructure somewhat than merely altering the sender data on a traditional spoofed e mail.
Revolut mentioned that mixture led it to meet the request, believing it got here from an genuine authorities authority. The agency found the downside after contacting the company individually, then alerted officers to the unauthorized mailbox and blocked the sender internally.
Former Mt. Gox CEO Mark Karpelès, who circulated a duplicate of the notification Saturday, argued that figuring out the compromised authorities company may enable different banks and exchanges to find out whether or not additionally they obtained data calls for from the similar mailbox. Revolut has to this point withheld the company’s id whereas it investigates.
That leaves the verification sequence as the key unresolved difficulty. Revolut has defined why the e mail regarded genuine, however has but to say whether or not authorities data requests require affirmation outdoors e mail, why it contacted the company solely after releasing buyer information, or whether or not it has modified that course of since discovering the fraud.
The publish Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers appeared first on CryptoSlate.
